No video

Azure AD Pass-through Authentication and Seamless Single Sign-on

  Рет қаралды 128,845

Microsoft Mechanics

Microsoft Mechanics

Күн бұрын

Watch Senior Program Manager Microsoft Identity Services, Swaroop Krishnamurthy, show you a new way you can harness the power of cloud authentication while still keeping your passwords on-premises using Azure Active Directory pass-through authentication and
seamless single sign-on capabilities.
You'll see how Azure AD can now validate securely your passwords against on-premises Active Directory all without the need for expensive on-premises infrastructure and automatically sign your users in while they're at work.

Пікірлер: 26
@say2merohit
@say2merohit 10 ай бұрын
still relevant in 2023 I keep coming back to this every other time
@bobbymoore868
@bobbymoore868 4 жыл бұрын
I love this channel. A massive massive help; simple, clear and well structured.
@raydavis3697
@raydavis3697 8 ай бұрын
Great video. Thank you.
@mavaddat
@mavaddat 6 жыл бұрын
This is so cool! And what a helpfully concise and easy to understand run through of how to set it up.
@JoseRodriguezFrio
@JoseRodriguezFrio 3 жыл бұрын
This was available in 2017?? wow, good stuff
@say2merohit
@say2merohit 3 жыл бұрын
Love the content and Music is great too
@KarthikS30712
@KarthikS30712 9 ай бұрын
That IE logo!
@edohio435
@edohio435 6 жыл бұрын
I wish it was more clear if you can use Microsoft MFA and this technique. I keep seeing conflicting notes on this. I understand 3rd party MFA but can you use MS MFA and this AD Connect SSO?
@Trent_Plays
@Trent_Plays 6 жыл бұрын
What about when the user is not on the corporate LAN? or the computer is not domain joined?
@MSFTMechanics
@MSFTMechanics 6 жыл бұрын
If the machine was on the local network, then connects to a resource from outside the local network, the Kerb ticket has a limited validity window for a few hours so if you connect when you get home for example home it doesn't re-prompt for creds. Once that ticket does expire, it will fallback to re-prompt for creds.
@BrendanMetcalfe
@BrendanMetcalfe 4 жыл бұрын
Thanks!
@biaz666
@biaz666 6 жыл бұрын
Is Seamless Single Sign-on with hash sync possible for multiple on-prem domains?
@henreeneo
@henreeneo 6 жыл бұрын
Hi Guys, Thanks for this video. I'm currently facing a dilemma. I set up SSO via AD connect and all works fine. But i created a scenerio where i turned off my on premise servers and after a few minutes i keep getting prompts to enter my password for office365 on my mobile device and on my laptop as well. Please what could the issue be. I enabled password sync but this is really strange. I thought password sync enables cloud storage of passwords so i can login to O365 even when my on premise server is down
@glennquag3838
@glennquag3838 4 жыл бұрын
Hi just learning about SSO setting up the method above will I still be able to have password changes made to on-premise active directory or suspending/deleting accounts be automatically synced still?
@MSFTMechanics
@MSFTMechanics 4 жыл бұрын
Yes, with pass through authentication, password hash sync or ADFS, those changes will replicate. Having worked in IT though, I think setting up password writeback to the on premises directory service is even better than mastering in AD on prem. Also will reduce helpdesk calls if users now can't access the domain easily outside the office.
@thaddeusbrown1009
@thaddeusbrown1009 6 жыл бұрын
On the same lines as Michel Dumont, we used password hash sync for user sign in. Instructions say you can use Password Hash sync with SSO. However later on in the video it says you don't want to pass hashes to the cloud. Can you add some clarity to that?
@MSFTMechanics
@MSFTMechanics 6 жыл бұрын
The option is an alternative to password hash sync. Even though password hash sync is a great option, secure and easiest to implement, some organizations still prefer not syncing anything related to a password to the cloud (even a hash of a hash). AD Federation Services then used to be only way to redirect auth to an on premises server. Now Pass Through Auth gives you another option if you don't want to sync password hashes.
@miked.4786
@miked.4786 6 жыл бұрын
I'm confused. Is unchecking password synchronization a requirement for Seamless Sign-On to work ?
@MSFTMechanics
@MSFTMechanics 6 жыл бұрын
+Michel Dumont Seamless SSO works with Pass through Authentication or Password Hash Sync. The reason Swaroop unchecked Password Sync was because he was configuring Pass Through Authentication. -Jeremy
@ankur9952
@ankur9952 7 жыл бұрын
How is the Outlook Client Experience using Seamless SSO with Pass-through Auth ? Does It works for non-domain join Machine ?
@MSFTMechanics
@MSFTMechanics 7 жыл бұрын
Yes - you'll need to still run the Outlook client's first run experience to add the account for the email OST to start building, but after that SSO will be automatic and that is true for the other signed-in Office apps as well.
@ankur9952
@ankur9952 7 жыл бұрын
Thanks for your response. In case if Outlook Profile is already build and connected to Exchange Online and now if I have set up Seamless SSO then it should prompt for the first time and then it should do automatic login ? Or I need to create a new Outlook Profile?
@Wittysomethinghere
@Wittysomethinghere 7 жыл бұрын
Does the SSO extend into O365 installed apps on the end point (e.g. Outlook, Word, OneDrive, ...)?
@MSFTMechanics
@MSFTMechanics 7 жыл бұрын
Yes - see question from Ankur earlier. First run experiences (FRE) in cases still need to run for initial config, but ongoing authentication and authorization should work in run state. -Jeremy
@gvgandhi
@gvgandhi 4 жыл бұрын
Jeremy seems to know nothing
@MSFTMechanics
@MSFTMechanics 4 жыл бұрын
Thanks Vinay! -Jeremy
Azure AD Pass through authentication
13:12
Microsoft Mechanics
Рет қаралды 46 М.
Azure AD Joined SSO Access to AD Joined Resources!
20:41
John Savill's Technical Training
Рет қаралды 22 М.
Underwater Challenge 😱
00:37
Topper Guild
Рет қаралды 33 МЛН
Or is Harriet Quinn good? #cosplay#joker #Harriet Quinn
00:20
佐助与鸣人
Рет қаралды 5 МЛН
Meet the one boy from the Ronaldo edit in India
00:30
Younes Zarou
Рет қаралды 19 МЛН
🩷🩵VS👿
00:38
ISSEI / いっせい
Рет қаралды 26 МЛН
Azure Active Directory Multi Factor Authentication and Security defaults
15:42
How does Pass Through Authentication ( PTA ) Work ?
9:53
The Cloud Mentor
Рет қаралды 1,1 М.
Azure Active Directory (AD, AAD) Tutorial | Identity and Access Management Service
30:57
Adam Marczak - Azure for Everyone
Рет қаралды 704 М.
Windows Autopilot: What it is and how it works
20:19
Microsoft Mechanics
Рет қаралды 123 М.
Azure AD Understanding Tokens
21:55
John Savill's Technical Training
Рет қаралды 77 М.
Deploy Azure AD Domain Service and Join a Server to the Domain
26:57
Travis Roberts
Рет қаралды 114 М.
Microsoft Entra ID | Azure Active Directory Joined Devices
15:31
Concepts Work
Рет қаралды 24 М.
Azure AD App Registrations, Enterprise Apps and Service Principals
33:44
John Savill's Technical Training
Рет қаралды 219 М.
What is Entra ID, Entra Domain Services, and Windows AD?
8:44
Travis Roberts
Рет қаралды 15 М.
Identity Architecture: PHS and PTA Authentication | Microsoft Entra ID
7:24
Underwater Challenge 😱
00:37
Topper Guild
Рет қаралды 33 МЛН